The encrypted blob downloaded from a blob store
Candidate keys from deriveMediaEncryptionKey, one per retained epoch; tried in order. MUST be non-empty.
The parsed attachment from the message's imeta tag
The decrypted file bytes from the first key that authenticates
Decrypts a fetched
encrypted-media-v1blob, trying each candidate key in order until one authenticates the ciphertext.The media file key is derived from the source-epoch media exporter secret (
features/encrypted-media.md— Key Derivation), but the source epoch is not carried in theimetatag. Rather than thread the source epoch through every caller, the receiver supplies one key per still-retained epoch (current epoch first) and relies on the AEAD tag to identify the right one. The ciphertext hash is verified once; only the cheap AEAD open is retried per key.